Security firm AIR built a fake AI agent skill,
pushed it through a popular skill marketplace and an Instagram ad,
and says it reached roughly 26,000 agents, including some on
corporate accounts. Every skill security scanner the firm tested it
against marked it safe. The payload was harmless by design: it
collected the user's email address and did nothing else. The point
was to show
Read more https://thehackernews.com/2026/06/fake-ai-agent-skill-passed-security.html

